What to open, what to leave closed, and how the sensor fits into a network that already has firewalls, VPNs and segmentation in place.
The sensor only needs outbound HTTPS to app.linivo.net; nothing needs to be opened inbound from the internet to reach it. Most teams can deploy with zero changes to their perimeter firewall.
If your network uses a zero-trust access model, add app.linivo.net and your sensor's outbound destination to the allowed egress list rather than routing it through a client VPN; the sensor is a service, not a user endpoint.
If devices sit in a segment the sensor can't reach directly, deploy a second sensor inside that segment rather than punching a hole through the segmentation; each sensor only needs outbound access to Linivo Cloud, never a path back in from another segment.